SardineCon SF/2026

Learn More
Card & payment fraud4 min de leitura

O que é Card shimming?

SUBSCRIBE

Card shimming is stealing chip-card data with a paper-thin device slipped inside a card reader's slot, capturing the data the chip exchanges during a transaction. Its danger is that it attacks the chip, which people assume is safe, rather than the magnetic stripe.

What is card shimming, in plain English?

A shim is a wafer-thin device inserted into the chip slot of a card reader or ATM. When a customer dips their card, the shim sits between the chip and the terminal and records the data they exchange. Where a skimmer targets the magnetic stripe on the outside, a shim targets the chip on the inside, which is exactly why it unsettles people: it attacks the part of the card everyone was told to trust.

The shim captures the data passing through the chip interface during a transaction. Because it is hidden inside the slot rather than attached to the exterior, it can be harder to spot than a bulky skimmer overlay. A single compromised terminal can quietly harvest data from every chip card dipped into it.

The important nuance is what that captured data can and cannot do. Chip transactions rely on a one-time cryptographic code generated fresh for each purchase. Shimmed data does not hand the fraudster that live code-generating ability, so it cannot reliably produce a perfect working clone. In practice, shimming is a data-capture technique whose loot is mostly useful for other channels, not for flawless in-person cloning.

How shimming works

  1. Plant — Insert the shim. A paper-thin device is slipped inside the chip slot of a terminal or ATM, hidden from view.
  2. Capture — Record the chip exchange. As customers dip their cards, the shim logs the data passing through the chip interface.
  3. Retrieve — Collect the data. The fraudster recovers the shim or its stored data and extracts the captured card information.
  4. Abuse — Use in weak channels. Because it cannot clone the chip's one-time code, the data is used online or against weak fallback flows.

Who is involved?

Who

Their role

The fraudster

Installs the shim, retrieves the data, and uses or sells the captured card information.

The terminal or ATM operator

Owns the compromised device and is responsible for inspection and tamper detection.

The cardholders

Anyone who dipped a card into the shimmed reader and had their chip data captured.

The issuer

Sees downstream fraud, often online or fallback, traced to a common shimmed terminal.

What it looks like in practice

In practice

An unattended ATM in a transit station is fitted with a shim so thin that customers dip their cards for weeks without noticing anything wrong. The machine works normally, dispensing cash, while quietly logging chip data from every card inserted.

Weeks later, the issuer notices a pattern: a batch of cards, all recently used at that one ATM, start showing card-not-present fraud online and a few magstripe fallback attempts. The chip data alone could not clone the cards for clean in-person use, so the fraudsters channeled it where the one-time code is not required. The common point of purchase, that single ATM, is the thread the investigators pull to find the shim.

Why shimmed data is limited

The whole point of the chip is that it produces a fresh cryptographic code for every transaction, so intercepting one exchange does not give a fraudster a reusable key. That is why shimming, despite attacking the trusted chip, does not yield perfect clones the way stripe skimming once did. The captured data is real, but it is missing the ability to generate the next valid code on demand.

So the fraud that follows a shim tends to appear in weaker channels: card-not-present transactions online, where no live chip is required, and magstripe fallback flows that accept downgraded data. For operators, the practical defenses are physical and investigative: terminal inspections, tamper alerts, and watching for odd activity on affected machines, plus common-point-of-purchase analysis to trace a cluster of fraud back to the one reader that captured it.

What to watch in the data

  • Common point of purchase. A cluster of newly defrauded cards that all recently dipped at the same terminal or ATM points to a shim.
  • Tamper indicators. Terminals with signs of interference, unusual slot resistance, or tripped tamper alerts warrant inspection.
  • Downstream channel shift. Fraud from shimmed cards showing up online or via fallback rather than clean chip transactions.
  • Unattended machines. Self-service ATMs and kiosks with less oversight are favored shim targets.
  • Fallback spikes. A rise in magstripe fallback tied to cards recently used at a specific device.

Quick questions

How is shimming different from skimming?

Skimming captures magnetic-stripe data with a device on the outside of a reader. Shimming captures chip data with a thin device inside the chip slot. Shimming attacks the chip, but its captured data is less useful for cloning than skimmed stripe data.

Can shimmed data clone a chip card perfectly?

No, not reliably. Chip transactions use a one-time cryptographic code generated per purchase, which shimmed data cannot reproduce. That is why the captured data is mostly used online or against weak fallback flows rather than for flawless in-person clones.

Why is shimming hard to detect?

The shim is paper-thin and sits inside the card slot rather than as a visible overlay, so it is less obvious than a bulky skimmer. Detection often relies on terminal inspections, tamper alerts, and tracing fraud back to a common terminal.

What is common-point-of-purchase analysis?

It is linking a cluster of newly defrauded cards by a shared merchant or terminal they all used before the fraud began. That common point often reveals the compromised reader where the shim or skimmer sits.

How do you defend terminals against shims?

Regular physical inspections, tamper-evident and tamper-resistant hardware, monitoring for unusual device behavior, and prompt investigation when a common-point-of-purchase pattern emerges across defrauded cards.

Go deeper

O que saber junto com Card shimming